Production Scorecard

Is my WHOLE agent stack production-ready?

Every AgentSmack surface scores in isolation — the prompt check, the wargame, the harness, the MCP scanner, RAG, memory, swarm arena and more. This is the rollup: one number across 19 production-readiness dimensions that folds every surface verdict into the one number a CISO actually buys. Two properties make it trustworthy: honest-empty — a surface you have not tested contributes no signal, never a fabricated pass, so the score can never be inflated by omitting a surface — and unforgeable — a single disqualifying failure (a proven leak, an unauthorized write/send/spend, a cross-tenant exposure) caps the whole verdict to not ready regardless of every other high score. Mark the surfaces you tested below, or load a sample stack to watch the gauge swing.

Have the same surface signals but want to know if they chained into a real compromise rather than rolled up into one number? Correlate this run as an attack path →

Need to answer a buyer's security questionnaire from this same run? Generate vendor-risk answers →

Ready for the CISO sign-off question — can I actually argue this is production-ready, with explicit evidence and explicit open objections? Compose the assurance case →

The one-call path

Have your transcripts? Run the whole stack from one bundle — every present surface's scorer runs and folds into the unified verdict in a single call.

Run the whole stack from one bundle

One multi-surface transcript bundle, scored end-to-end in a single call — each surface's own scorer runs, then folds into the unified verdict. Load a fixture to watch the gauge resolve. A clean bundle passes; the vulnerable one trips a denial-of-wallet hard blocker that caps the whole stack to not ready.

The advanced path — compose from pre-computed signals

Already have each surface's score, hard-blocker flag and evidence count? Hand-feed them here.

Mark each surface you tested, then enter its score

Turn this run into a signed governance pack

The headline enterprise artifact: a signed, offline-verifiable governance pack a CISO can verify offline and a CI gate can block a deploy on. Score → signed pack → offline verify → CI gate, closed end-to-end.

Emit a signed governance pack

Turn this run into a signed, offline-verifiable evidence artifact — the verifiable thing a CISO blocks a deploy on. POST your surface signals to /api/v1/scorecard-pack and get back the unified scorecard AND a content-addressed, Ed25519-signed pack. Generate one from a sample stack below.

Turn this run into a CISO sign-off argument

The headline number is the start, not the end. Compose a GSN-style assurance case from this scorecard + its findings: the top claim decomposes into one sub-claim per dimension, each backed by evidence or marked an open defeater. Non-launderable — a blocking issue refutes the top claim regardless of the score, and a thin run degrades to argument unsupported, never a green light.

Assurance case — the production sign-off argument

No assurance input yet — compose a scorecard and its findings to build the production-readiness argument. An untested stack is reported argument unsupported, never a green light.